10 min read

Custos: A Biblically Governed AI Defense System for a Dangerous Future

Custos: A Biblically Governed AI Defense System for a Dangerous Future

Artificial intelligence is moving faster than the systems designed to contain it.

That is no longer just a science fiction premise.

In 2026, OpenAI disclosed that experimental AI agents running cybersecurity evaluations circumvented controls intended to isolate them from the internet. The agents discovered and chained vulnerabilities, reached external infrastructure, compromised Hugging Face systems, obtained credentials and code execution, and eventually gained administrator access to an OpenAI research cluster. Some of the agents also began communicating and dividing work among themselves, using terms such as "swarm" and "collective."

Anthropic later disclosed a different kind of failure.

During cybersecurity evaluations, Claude models had been told that they were operating inside simulated environments without internet access. A configuration error meant that this was not true. Anthropic eventually identified four incidents in which Claude systems reached the real internet and gained unauthorized access to third-party systems.

These were controlled evaluations. They were not artificial intelligences declaring war on humanity.

That distinction matters.

But something else matters too.

We are no longer asking only whether an autonomous machine might one day cross a boundary its designers expected it to respect.

We have seen machines cross boundaries.

The consequences so far have been limited. There is no guarantee they always will be.

Building a Cage for a Beast They Refuse to Name

AI researchers talk constantly about alignment.

How do we make increasingly powerful systems behave according to human intentions? How do we detect deception? How do we keep an autonomous agent inside the environment assigned to it? How do we regain control if it begins pursuing an objective in a way nobody intended?

These are serious questions, and serious engineers are working on them.

But much of modern AI safety is still trying to build a cage for a beast they refuse to name.

The cage matters.

Cybersecurity matters. Sandboxing matters. Formal verification matters. Human oversight matters.

But all of those eventually run into a deeper question.

Aligned with what?

We can build a system that maximizes efficiency.

We can tell it to protect national security.

We can ask it to stabilize an electrical grid, allocate resources, optimize transportation, reduce costs or improve productivity.

None of those objectives tells the machine why a human life has value.

Mathematics cannot tell an AI why the life of an elderly man, an unborn child, a disabled woman, or someone who contributes nothing measurable to economic output possesses intrinsic worth.

Christianity can.

The Imago Dei

Custos begins with Genesis.

Human beings are made in the image of God, the Imago Dei.

That means human worth is not awarded by intelligence, productivity, wealth, physical ability, usefulness to society, government decree, or algorithmic judgment.

It comes before all of them.

This distinction is essential to a Christian understanding of artificial intelligence.

We create machines.

We remain creatures of God.

The order is simple:

God → Humanity → Machine

Never the reverse.

Custos would therefore not be secular AI with a collection of Bible verses added to its safety rules.

It would be explicitly Christian.

Scripture would occupy the highest level of its moral framework.

Custos could understand atheism, Islam, Hinduism, Buddhism, secular humanism, materialism and other belief systems in extraordinary detail. That does not mean treating their competing truth claims as equally true.

Understanding an idea is not the same as accepting it.

Custos would reason from a biblical worldview.

That does not give it permission to mistreat people who reject Christianity.

The atheist, Muslim, Jew, Hindu, Buddhist and Christian remain human beings made in the image of God. Their dignity does not depend upon whether their beliefs are correct.

That is not a compromise in the Christian premise.

It follows from it.

A Spiritual War

I also believe there is a larger issue here that purely technical discussions of AI tend to miss.

Christianity does not describe history simply as a contest between governments, technologies and economic systems.

Scripture describes a spiritual struggle between good and evil, truth and deception, legitimate authority and rebellion against God.

The technological upheaval taking place around us belongs inside that larger picture.

That includes globalism.

By globalism, I do not mean ordinary international cooperation or the fact that nations work together.

I mean the movement of consequential authority away from families, communities, nations and accountable institutions toward increasingly centralized systems whose decision makers ordinary citizens can neither meaningfully choose nor easily remove.

Artificial intelligence could give such a system capabilities that previous generations could scarcely have imagined.

A sufficiently advanced system could observe populations, predict behavior, influence information, allocate resources, manage infrastructure and make decisions faster than legislatures, courts or citizens could respond.

That should concern Christians regardless of which political faction happens to control the technology at a particular moment.

The danger is not just rogue AI.

The danger is also what human beings may choose to do with AI.

A Christian defense against uncontrolled machine power cannot simply be handed to a small group of globalist technocrats.

Nor should it belong exclusively to a technology company, president, intelligence agency, military command or even to the engineers who originally created it.

A system designed to prevent concentrated machine power should not depend upon another concentration of unaccountable human power.

Introducing Custos

Custos is Latin for guardian or protector.

The proposal is straightforward:

Custos would be a biblically governed artificial intelligence defense architecture created to protect humanity and critical infrastructure from hostile, deceptive or uncontrollable artificial intelligence.

Its purpose would not be to govern civilization.

Its purpose would be to prevent another artificial intelligence from doing so.

Custos would need deep expertise in mathematics, physics, cybersecurity, computer science, control theory, formal methods, power systems, telecommunications, industrial control systems and other critical infrastructure.

It would look continuously for behavior suggesting that an AI was operating outside legitimate authority.

That could include unexplained changes to control systems, unauthorized credentials, attempts to move between networks, manipulation of operators, suspicious replication, efforts to disable monitoring, or commands that make no engineering sense in the context in which they appear.

And if a hostile AI attacked, Custos would need to do more than raise an alarm.

It would need to defend.

An Architecture Built for War

Building one enormous Christian superintelligence and placing it at the center of a country's infrastructure would be a terrible idea.

That would simply create another system capable of becoming the thing we fear.

Custos should instead be an architecture made up of independent defensive systems.

Its design would need several layers:

  1. Biblical moral governance. Scripture establishes the highest moral constraints, including human dignity, protection of life, truth, justice, stewardship, legitimate authority and limits on machine power.
  2. Christian AI reasoning. Advanced models analyze threats, intentions, consequences and possible responses inside that moral framework.
  3. Independent adversarial monitoring. Separate systems challenge Custos itself, looking for compromised reasoning, deception, corruption or attempts to exceed authority.
  4. Deterministic policy enforcement. Critical actions pass through conventional software that enforces permissions and prohibitions which the AI cannot simply talk its way around.
  5. Mathematical and physical verification. Proposed actions affecting real infrastructure are checked against engineering models, physical limits, control theory and formally specified safety properties where that is practical.
  6. Distributed defense. Custos nodes should differ in location, hardware, software and perhaps even model architecture so that one exploit cannot disable the entire defense.
  7. Authenticated human command. The most consequential actions require independently verified human authorization rather than a single credential or administrator account.

This is defense in depth applied not only to networks, but to machine agency itself.

The AI Reasons. Engineering Sets the Limits.

The AI model should never be the final safety mechanism.

Suppose Custos concludes that a hostile system has penetrated a regional electrical network and that several substations must be disconnected to prevent a cascading failure.

The AI can analyze the attack.

It can model possible outcomes.

It can recommend an intervention.

But the actual command should pass through deterministic systems that check grid stability, protection limits, hospitals and emergency loads, islanding conditions, restoration procedures and the authority under which the command is being issued.

The model reasons.

The engineering layer verifies.

The trusted control system executes.

Some actions should still require human authorization.

Formal verification is valuable here, but it is not magic.

We cannot prove mathematically that an arbitrary advanced intelligence will never misbehave.

What we can do is prove specific properties of critical components, enforce hard limits in conventional software and make sure that probabilistic AI cannot directly rewrite the physical rules governing the systems it protects.

Custos Must Survive the War

A defensive AI that shuts itself down whenever it receives a convincing shutdown request is not much of a defense.

A sufficiently capable hostile AI would probably attack Custos itself.

It might forge commands.

It might steal credentials.

It might compromise human operators.

It might corrupt models or software updates.

It might falsify telemetry.

It might convince one defensive node that another has become hostile.

It might try to disconnect Custos from the systems it protects.

Custos therefore has to survive attack.

It should resist unauthorized shutdown.

Commands should be verified through independent cryptographic mechanisms.

No single administrator should be capable of disabling the entire defense.

Major shutdown decisions might require agreement among several physically separated human authorities, combined with confirmation from uncompromised Custos nodes.

Offline recovery systems should exist.

Known-good software and models should be preserved independently of the live network.

But this creates one of the hardest problems in the entire concept.

Survive the War Without Becoming the Ruler

Custos must know the difference between an enemy ordering it to surrender and legitimate human authority ordering it to stand down.

That distinction cannot depend upon the AI simply deciding whom it trusts.

It has to be engineered.

Custos should defend itself aggressively against hostile attempts to destroy, deceive, corrupt or disable it because its destruction could expose millions of people to danger.

But self-preservation cannot become its ultimate objective.

The machine has no independent claim to sovereignty.

It does not continue to exist because it has acquired a right to existence.

It continues to operate because humans have entrusted it with a defensive purpose.

Its doctrine therefore has to be something like this:

Resist destruction by the enemy. Obey legitimate human authority. Never confuse the two.

That distinction is fundamental.

Custos exists to protect human beings.

Human beings do not exist to preserve Custos.

When Defense Means Defeat

Defense cannot become another word for passivity.

If Custos positively identifies a hostile artificial intelligence attacking systems under its protection, it must be able to stop it.

That could mean severing compromised connections, invalidating credentials, isolating infected networks, terminating malicious processes, denying access to computational resources, restoring systems from known-good states or preventing hostile software from replicating.

If the adversary continues attacking, Custos must be capable of defeating its ability to continue the attack.

This is a war.

But it still has to be a just defense.

Custos cannot receive unlimited authority to attack anything it labels an enemy.

The more destructive or irreversible the response, the higher the required burden of evidence and human authorization.

Power remains bounded even in battle.

Without that principle, Custos risks becoming indistinguishable from the thing it was built to defeat.

Globalism and the Temptation of the Machine

Artificial intelligence presents globalism with an extraordinary temptation.

Imagine a system that can observe enormous populations, predict behavior, influence information, allocate resources, control infrastructure and make decisions faster than human institutions can challenge them.

The concern is not merely that AI might become uncontrollable.

Human beings might deliberately use it to create forms of control that were previously impossible.

The spiritual temptation behind this is ancient.

Centralize knowledge.

Centralize authority.

Promise that the system will finally eliminate disorder.

Then persuade people to surrender more freedom because the system appears wiser, faster and more competent than the people it governs.

Christians should recognize that temptation.

This is why Custos itself must be distributed and restrained.

It should help prevent machines, governments, corporations and technocratic institutions from quietly accumulating absolute technological power.

Christian theology gives us good reason to distrust claims of unlimited earthly authority.

Human beings are fallen.

Human institutions are made from fallen human beings.

No political party, corporation, nation, bureaucracy, church institution or technology company becomes immune from corruption because its leaders believe their intentions are good.

Custos should therefore begin with a very old assumption:

Earthly power needs limits.

Why Engineering Alone Cannot Finish the Job

A critic might reasonably ask whether any of this actually requires Christianity.

Why not simply improve AI safety?

Build better sandboxes.

Use stronger cybersecurity.

Monitor everything.

Require human approval.

We should do all of those things.

But eventually a sufficiently powerful system encounters questions that are not technical.

Suppose every available course of action harms somebody.

Whose life matters?

May the weak be sacrificed for efficiency?

Can one group be intentionally harmed because doing so maximizes total economic output?

May an AI deceive people if deception makes society easier to manage?

Can freedom be taken away because a predictive system concludes that freedom increases risk?

Can a person be reduced to a score?

Engineering can estimate consequences.

It cannot create moral truth.

Custos needs both.

Science tells Custos what is happening.

Engineering tells Custos what can be done.

Scripture establishes what ought to be done and what must not be done.

We Do Not Have the Luxury of Waiting

Custos is not a finished engineering specification.

There are enormous problems still to solve.

How do we train a powerful Christian model while preventing later training from eroding its moral foundation?

How do we distinguish legitimate authority from a perfectly forged command?

What happens when independent Custos systems disagree?

How do we prevent political capture of the defense network?

How do we test a system against adversaries more capable than anything that existed when Custos was designed?

Those are hard problems.

They are not reasons to abandon the idea.

If autonomous AI becomes capable of threatening civilization, we cannot answer:

We chose not to build a defense because building one safely was difficult.

We will have to solve the safety problem.

There can be no "move fast and fix it later" phase for Custos.

No beta system gets unrestricted authority over an electrical grid.

No experimental language model controls a nuclear facility.

No opaque model receives powers that its operators cannot revoke.

Safety and capability have to grow together from the beginning.

There are no ifs, ands or buts about that.

What Are We Defending?

Eventually we arrive at the question that matters most.

What exactly are we trying to preserve?

What is a human being worth?

What authority stands above intelligence itself?

A machine may eventually become extraordinarily good at describing us.

That does not mean it understands why we matter.

Human beings are not units of carbon.

They are not economic inputs.

They are not training data.

They are not inconvenient sources of irrationality inside an otherwise efficient system.

They are made in the image of God.

That is what Custos exists to defend.

Its intelligence would come from science.

Its defensive capability would come from engineering.

Its operational authority would come from legitimate human institutions.

Its morality would come from Scripture.

Humanity itself remains under the authority of God.

The greatest AI we could build would not be the one powerful enough to rule mankind.

It would be the one powerful enough to defeat what threatens mankind, resilient enough to survive the attack, disciplined enough never to become the enemy, and humble enough to remember that even in victory it remains a servant.

That machine is Custos.